10.1.2.2 Purpose of National Cybersecurity Framework Flowchart
The flowchart is Figure 17 provides a high-level view of how a country may create an
overall cybersecurity governance framework. The flowchart outlines minimum-security
measures that all stakeholders must abide by. As we see under Means, the governance
framework also serves as the basis for critical activities such as risk management.
10.1.2.3 Stage 0 – Relevant Driver
A number of events may drive the formulation of national cybersecurity frameworks. The
adoption of national cybersecurity legislation is a typical example. Whatever the origin,
national frameworks typically define core security principles and standards that apply to
a wide range of stakeholders and thus communicate the security goals.
10.1.2.4 Stage 1 – National Cybersecurity Framework Working Group
We underscore the government’s accountability for cybersecurity throughout this Guide.
It is no surprise then that we would expect a focal government organisation to create and
orchestrate the national cybersecurity framework working Group. We further expect the
participation of all organisations that handle and/or use information critical to advancing
national interests. Countries may choose to limit the list to organisations responsible for
local and national government data including contractors. Working groups also typically
enlist the input organisations with technical and information assurance competencies.
Lastly, flowchart envisages a possible role for allies and other international partners.
10.1.2.5 Stage 2 – Define Framework Integration Plan
We noted in stage 1 that it might be practical to limit the working group’s membership to
organisations that handle and process government information. Whatever approach a
nation chooses, it is crucial to ensure that all stakeholders have a governance structure
similar to the national cybersecurity framework. For example, a State would have major
gaps in the implementation of its strategy if the private sector, which owns and operates
the critical infrastructure, does not follow any sort of framework. Therefore, this stage
ensures that all frameworks coherently support the national cybersecurity strategy goals.
10.1.2.6 Stage 3 – Communicate Cybersecurity Framework
This stage calls for the creation of an efficient mechanism for ensuring all stakeholders
know about the cybersecurity framework as well as any changes to it.
10.1.2.7 Stage 4 – Cybersecurity Framework Implementation
At this stage, all relevant stakeholders must demonstrate compliance with the minimumsecurity requirements. The stage also requires stakeholders to demonstrate compliance
with security obligations that apply to specific risk profiles as required by national bodies.